Microsoft Certified:Azure Network Engineer Associate
The Microsoft Certified: Azure Network Engineer Associate certification validates your ability to design, implement, and manage Azure networking solutions. It is aimed at network engineers responsible for optimizing performance, resiliency, and security of Azure networking solutions. Earning it demonstrates your expertise in managing Azure networking infrastructure and services.
537 practice questions · Updated 2026-07-29
5Domains
16Objectives
140Concepts
537Questions
AZ-700 Curriculum
Every domain, objective, and concept the AZ-700 exam measures.
- Network Segmentation Planning
- Virtual Network Creation
- Subnetting Configuration
- Subnet Delegation Planning
- Shared vs Dedicated Subnets
- Public IP Prefix Creation
- Public IP Address Prefix Usage
- Custom IP Address Prefix Implementation
- Public IP Address Creation
- Public IP Address Association
- VNet Name Resolution Design
- VNet DNS Configuration
- Public DNS Zone Design
- Private DNS Zone Design
- Public DNS Zone Configuration
- Private DNS Zone Configuration
- Private DNS Zone Linking
- Azure DNS Private Resolver Implementation
- Service Chaining Design
- VNet Peering Implementation
- Azure Virtual Network Manager Connectivity
- User-Defined Routes Design
- Route Table Association
- Forced Tunneling Configuration
- Routing Issue Diagnosis
- Azure Route Server Design
- Azure NAT Gateway Use Cases
- Azure NAT Gateway Implementation
- Azure Network Watcher Configuration
- Network Health Monitoring
- Azure Monitor for Networks
- DDoS Protection Activation
- Secure Score Evaluation
- Attack Path Analysis Evaluation
- Cloud Security Explorer Utilization
- VPN Connection Design
- Virtual Network Gateway SKU Selection
- VPN Connection Implementation
- Policy vs Route-Based VPN
- Local Network Gateway Configuration
- IPsec/IKE Policy Configuration
- Virtual Network Gateway Configuration
- Connectivity Issue Diagnosis
- Azure Extended Network Implementation
- Virtual Network Gateway SKU Selection
- Tunnel Type Configuration
- Authentication Method Selection
- RADIUS Authentication Configuration
- Microsoft Entra ID Authentication
- VPN Client Configuration File Implementation
- Client-Side Issue Diagnosis
- Always On VPN Azure Requirements
- Azure Network Adapter Requirements
- ExpressRoute Connectivity Models
- ExpressRoute SKU and Tier Selection
- Cross-Region Connectivity Design
- ExpressRoute Redundancy and Disaster Recovery
- Global Reach Implementation
- FastPath Configuration
- ExpressRoute Direct Implementation
- Azure Private Peering Configuration
- Microsoft Peering Configuration
- ExpressRoute Gateway Configuration
- Virtual Network Connection to ExpressRoute
- Route Advertisement Configuration
- ExpressRoute Encryption
- Bidirectional Forwarding Detection
- ExpressRoute Troubleshooting
- Virtual WAN SKU Selection
- Virtual WAN Architecture Design
- Virtual Hub Creation
- Gateway Scale Unit Selection
- Gateway Deployment
- Virtual Hub Routing Configuration
- Third-Party NVA Integration
- Azure Load Balancer Features
- Azure Load Balancer Use Cases
- Azure Load Balancer SKU Selection
- Public vs Internal Load Balancers
- Regional vs Cross-Region Load Balancers
- Azure Load Balancer Configuration
- Azure Traffic Manager Implementation
- Gateway Load Balancer Implementation
- Load Balancing Rule Implementation
- Inbound NAT Rules Configuration
- Outbound Rules Configuration
- Azure Application Gateway Features
- Use Cases for Azure Application Gateway
- Scaling Options
- Backend Pool Creation
- Health Probes Configuration
- Listener Configuration
- Routing Rules Setup
- HTTP Settings Configuration
- TLS Configuration
- Rewrite Rule Sets
- Azure Front Door Features
- Azure Front Door Use Cases
- Azure Front Door Tier Selection
- Azure Front Door Configuration
- TLS Termination Configuration
- Caching Configuration
- Traffic Acceleration
- Rules and URL Management
- Azure Private Link Security
- Understand Private Endpoints
- Plan Private Endpoint Deployment
- Create Private Endpoints
- Configure Private Endpoint Access
- Understand Private Link Service
- Create Private Link Service
- DNS Integration with Private Link
- On-Premises Integration with Private Link
- Service Endpoint Purpose
- Service Endpoint Scenarios
- Creating Service Endpoints
- Service Endpoint Policies
- Access Configuration for Service Endpoints
- NSG Creation
- NSG Association
- ASG Creation
- ASG Association
- NSG Security Rules
- Virtual Network Flow Logs Implementation
- Virtual Network Flow Logs Interpretation
- IP Flow Verification
- NSG Remote Administration Configuration
- Azure Virtual Network Manager Security
- Azure Firewall Features
- Azure Firewall SKU Selection
- Azure Firewall Deployment Design
- Azure Firewall Deployment Implementation
- Azure Firewall Rule Configuration
- Azure Firewall Manager Policies
- Secure Hub with Azure Virtual WAN
- WAF Features and Capabilities
- WAF Requirement Mapping
- WAF Deployment Design
- WAF Policy Configuration
- WAF Detection Mode
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for AZ-700, so none is invented.